IP Library Patent Application 15166300
Patent Application
App. No. 15/166,300

SYSTEMS AND METHODS FOR COMBINED OTP AND KBA IDENTITY AUTHENTICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/166,300
Abstract

Certain implementations include systems and methods for combined one-time- passcode (OTP) and knowledge-based-authentication (KBA) identity authentication. A method is provided that includes receiving a set of identity information associated with a subject; querying one or more databases; receiving personally identifiable information; producing at least one knowledge based authentication (KBA) identity proofing question having a personally identifiable correct answer; generating a unique correct one-time pass (OTP) code for the personally identifiable correct answer; generating one or more incorrect answers with corresponding incorrect codes; outputting, the at least one KBA identity proofing question; outputting the personally identifiable correct answer with the unique correct OTP code, and the one or more incorrect answers with corresponding incorrect codes; receiving a response code; comparing the response code and the unique correct OTP code; and responsive to a match between the response code and the unique correct OTP code, outputting a first indication of authentication.

Claims (53)

1 . A computer-implemented method comprising:

receiving a set of identity information associated with a subject;

querying one or more databases with at least a portion of the set of identity information;

receiving, in response to the querying, personally identifiable information;

producing, with one or more computer processors, and based at least in part on the personally identifiable information, at least one knowledge based authentication (KBA) identity proofing question having a personally identifiable correct answer;

generating a unique correct one-time pass (OTP) code for the personally identifiable correct answer;

sending, for display on a first computing device associated with the subject, the at least one KBA identity proofing question;

sending, for display on a second computing device associated with the subject, the personally identifiable correct answer with the unique correct OTP code, and one or more incorrect answers with corresponding incorrect codes;

receiving, responsive to the sending, a response code and at least one identifier related to the first computing device;

comparing the response code and the unique correct OTP code;

comparing the at least one identifier and the set of identity information associated with the subject;

responsive to a match between the response code and the unique correct OTP code, and responsive to a match between the at least one identifier and at least a portion of the set of identity information associated with the subject, sending, for display on the first computing device associated with the subject, a first indication of authentication.

2 . The method of claim 1 , wherein the at least one identifier related to the first computing device comprises one or more of: a phone number, an IP address, a MAC address, a location, an indication of signal-to-noise, browser configuration information, operating system information, a listing of installed fonts, and a listing of installed plug-ins.

3 . The method of claim 1 , further comprising sending, for display on the first computing device associated with the subject, an indication of authentication failure responsive to a determined mismatch between the at least one identifier and at least a portion of the set of identity information associated with the subject.

4 . The method of claim 3 , wherein the mismatch is determined based on a location of one or more of the first and second computing devices being associated with a geographical region having a high crime rate.

5 . The method of claim 1 , wherein the at least one KBA identity proofing question is sent via a first communication channel, and wherein the personally identifiable correct answer with the unique correct OTP code is sent via a second communication channel.

6 . The method of claim 5 , wherein the second communication channel differs from the first communication channel.

7 . The method of claim 1 , wherein the first computing device differs from the second computing device

8 . The method of claim 1 , further comprising:

receiving new biometric information associated with the subject;

querying one or more databases for previously stored biometric information associated with the subject;

comparing the new biometric information with the previously store biometric information; and

responsive to a match between the new and previously stored biometric information, sending, for display on one or more of the first computing device and the second computing device, a second indication of authentication.

9 . The method of claim 8 , wherein the biometric information comprises one or more of:

fingerprint image, voiceprint, facial feature image, and iris image.

10 . The method of claim 1 , wherein receiving the set of identity information comprises receiving, as applicable, one or more of: a name, an address, a birth date, a phone number, at least portion of a social security number, an IP address, a location, and a communication device electronic fingerprint.

11 . A system comprising:

at least one memory for storing data and computer-executable instructions; and at least one processor configured to access the at least one memory and further configured to execute the computer-executable instructions to:

receive a set of identity information associated with a subject;

query one or more databases with at least a portion of the set of identity information;

receive, in response to the querying, personally identifiable information;

produce, with one or more computer processors, and based at least in part on the personally identifiable information, at least one knowledge based authentication (KBA) identity proofing question having a personally identifiable correct answer;

generate a unique correct one-time pass (OTP) code for the personally identifiable correct answer;

send, for display on a first computing device associated with the subject, the at least one KBA identity proofing question;

send, for display on a second computing device associated with the subject, the personally identifiable correct answer with the unique correct OTP code, and one or more incorrect answers with corresponding incorrect codes;

receive, responsive to the sending, a response code and at least one identifier related to the first computing device;

compare the response code and the unique correct OTP code;

compare the at least one identifier and the set of identity information associated with the subject;

responsive to a match between the response code and the unique correct OTP code, and responsive to a match between the at least one identifier and at least a portion of the set of identity information associated with the subject, send, for display on the first computing device associated with the subject, a first indication of authentication.

12 . The system of claim 11 , wherein the at least one identifier related to the first computing device comprises one or more of: a phone number, an IP address, a MAC address, a location, an indication of signal-to-noise, browser configuration information, operating system information, a listing of installed fonts, and a listing of installed plug-ins.

13 . The system of claim 11 , wherein the at least one processor is further configured to execute the computer-executable instructions to send, for display on the first computing device associated with the subject, an indication of authentication failure responsive to a determined mismatch between the at least one identifier and at least a portion of the set of identity information associated with the subject.

14 . The system of claim 13 , wherein the mismatch is determined based on a location of one or more of the first and second computing devices being associated with a geographical region having a high crime rate.

15 . The system of claim 11 , wherein the at least one KBA identity proofing question is sent via a first communication channel, and wherein the personally identifiable correct answer with the unique correct OTP code is sent via a second communication channel.

16 . The system of claim 15 , wherein the second communication channel differs from the first communication channel.

17 . The system of claim 11 , wherein the first computing device differs from the second computing device

18 . The system of claim 11 , wherein the at least one processor is further configured to execute the computer-executable instructions to:

receive new biometric information associated with the subject;

query one or more databases for previously stored biometric information associated with the subject;

compare the new biometric information with the previously store biometric information;

responsive to a match between the new and previously stored biometric information, send, for display on one or more of the first computing device and the second computing device, a second indication of authentication; and

responsive to a mismatch between the new and previously stored biometric information, send, for display on one or more of the first computing device and the second computing device, an indication of a mismatch.

19 . The system of claim 11 , wherein the set of identity information comprises one or more of: a name, an address, a birth date, a phone number, at least portion of a social security number, an IP address, a location, and a communication device electronic fingerprint.

20 . The system of claim 11 , wherein a first communication channel is configured for communication with the first computing device, and wherein a second communication channel is configured for communication with the second computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2016
From: KNAUSS, BRYAN
To: LEXISNEXIS RISK SOLUTIONS INC.
Reel/Frame 038733/0505 →